Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type
Summary
| CVE | CVE-2026-102143 |
|---|---|
| State | PUBLISHED |
| Assigner | cisa-cg |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-30 21:17:03 UTC |
| Updated | 2026-10-01 02:17:43 UTC |
| Description | An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from 9119a7d8-5eab-497f-8521-727c672e3725
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Problem Types: CWE-306 | CWE-434 | CWE-306 CWE-306 Missing Authentication for Critical Function | CWE-434 CWE-434 Unrestricted Upload of File with Dangerous Type
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 9119a7d8-5eab-497f-8521-727c672e3725 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 3.1 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Kiteworks | Email Protection Gateway | affected 9.5.1 custom | Not specified |
| CNA | Kiteworks | Email Protection Gateway | unaffected 9.5.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-j... | 9119a7d8-5eab-497f-8521-727c672e3725 | github.com | |
| raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json | 9119a7d8-5eab-497f-8521-727c672e3725 | raw.githubusercontent.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Supr4s, https://yeswehack.com/hunters/supr4s (en)
CNA: wlayzz, https://yeswehack.com/hunters/wlayzz (en)
CNA: Icare, https://yeswehack.com/hunters/icare (en)
CNA: truff, https://yeswehack.com/hunters/truff (en)
There are currently no legacy QID mappings associated with this CVE.